BoardRunner: Automatic Firmware Rehosting Using High-Fidelity Compositional Device Models
Muhammad Hammad Bashir, Michael Rooney, Colin Smith, Dongyan Xu, Arslan Khan
Abstract
Artifact for the paper “BoardRunner: Automatic Firmware Rehosting Using High-Fidelity Compositional Device Models” (ACM CCS 2026). BoardRunner_CCS26_artifact_appendix.pdf and ARTIFACT.md provide the complete roadmap for artifact evaluation.The archive contains the complete source snapshot of FastDyn (commit 9c2e0b0 of https://github.com/PSecLab/FastDyn), including the BoardRunner examples, generated peripheral models, firmware binaries, and hardware I/O traces. It also includes the LibHW probe library (commit 6e53775), the patched QEMU fork (commit 99b5483), and the AFLNet fork (commit 509a103) at the exact commits used by the provided Docker images, together with the accepted paper and artifact appendix.Each experiment is packaged as a self-contained Docker image published on Docker Hub under pseclab/:fastdyn-slice:1.1.2halucinator-slice:1.0.1hitl-slice:1.0.1halucinator-macro:1.0.1halucinator-fd-macro:1.0.1boardrunner:1.0.0fastdyn-fuzzer:1.0.0The same images are archived here in docker-images.tar as seven docker save tarballs. Each image can be restored with:docker load -i pseclab-NAME-TAG.tar.gzAll experiments supporting the paper’s main claims (Figures 8a, 8b, and 9, and Tables 5–8) can be executed without physical hardware on an x86-64 Linux host with Docker.The hardware-dependent experiments are optional: Figure 8c, the Passthrough column of Table 6, and the hardware-assisted model baselines of Table 8. Reproducing them requires one or more of the following boards: STM32F429I-DISC1; NUCLEO-F103RB with a BME280 breakout; NUCLEO-H753ZI; STM32F769I-EVAL.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- SteamFuzz: Boosting Firmware Fuzzing via Automatic Message Window InferenceJorik van Nielen, Andreas Peter, Andrea ContinellaCCS 2026
- BFix: Automated Safe Memory-Leak Fixing for Binary CodeWen Zhang, Botang Xiao, Qingchen Kong, Boyang Yi et al.ICSE 2026
- Reproducing Web Application Vulnerabilities with Patch-Guided Routing Inference and Sink ExplorationYoukun Shi, Yuan Zhang, Feng Xue, Jiarun Dai et al.CCS 2026
- MnemonicHack: Recovering the Master Seed from Bitcoin Hardware Wallets via Side-Channel AttacksJiwoo Baek, Daehyeon Bae, Gyusang Kim, Gilsang Ahn et al.CCS 2026
- Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space EmulationHui Jun Tay, Kyle Zeng, Jayakrishna Menon Vadayath, Arvind S. Raj et al.USENIX Security 2023
